Forum Discussion

bls9701_10560's avatar
bls9701_10560
Icon for Nimbostratus rankNimbostratus
Mar 08, 2010

Output of Configuration

Hello,

 

 

Is there any way that I can request/intruct my f5 Admins to output all of the configuration data for my applications (pools, monitors, cookie settings, etc.) in some easy way?

 

 

I want to compare all of the applications to ensure consistency and check the correctness with regard to changes that have been made over time. I would also like to be able to compare that non-Prod is setup the same as Prod, etc.

 

 

As an SAP Admin, I don't have direct access to the f5, so it is difficult to keep track myself.

 

 

Thanks,

 

 

Brian

6 Replies

  • Nojan_Moshiri_4's avatar
    Nojan_Moshiri_4
    Historic F5 Account
    Are your f5 administrators aware of the "roles" feature that allows administrators such as yourself to access the systems in read-only mode?

     

    The roles include:

     

    Administrator - Complete access to all objects and configuration synchronization on redundant system pairs.

     

     

    Manager - Create, modify and delete virtual servers, pools, pool members, nodes, custom profiles, custom monitors and iRules(tm); view all objects.

     

     

    Application Editor - Modify nodes, pools, members and monitors; view all objects.

     

     

    Application Security Policy Editor - Complete control of the Application Security Manager; view all objects (analogous to administrator for BigIP systems with ASM installed).

     

     

    Operator - Enable and disable nodes and pool members; view all objects.

     

     

    Guest - View all objects.

     

     

     

    In the meantime, if your f5 administrator is comfortable with it, they could send you the bigip.conf itself, it's one way to read it (which is only okay if you're comfortable reading command line config and stitching it together) or they could take screen shots and send it to you.

     

     

    There might be another clever way to provide the same info.. I'll give it more thought or maybe someone else will chime in too. But as a regular and ongoing basis, I think having an role setup for you is essential.

     

     

  • Thank you for the response. I passed it on to the f5 Admin and was told that neither of those options are possible right now. I'm still open to other suggestions if anyone has any.

     

     

    Thanks,

     

     

    Brian
  • Brian,

     

     

    Would you be able to provide us with the version of BIG-IP code your company is using on the LTM's?

     

     

    Best Regards,

     

    John Clowers
  • Nojan_Moshiri_4's avatar
    Nojan_Moshiri_4
    Historic F5 Account
    If someone doesn't have time to take a simple screenshot to show you your configs, I don't see how any other option could be easier.

     

  • Hello,

     

     

    if you don't mind comparing text files, (with WinMerge or a similar program this is made easy) you could use a Single Configuration File (SCF) to capture the running config.

     

     

    use the cli command:

     

     

    b export

     

     

    output goes to /var/local/scf by default. Copy the file off with WinSCP or your prefered method and conpare between units.

     

     

    This sounds obvious, but it's a good idea to use the hostname and date for the filename to avoid later confusion!

     

     

    I hope this helps.
  • Brian,

     

    Another thing that you could ask for are the backup files over time and for a recent backup. These ucs files contain every file you would ever want to see...

     

     

    An alternative is to as for a qkview file. This is a backup file along with some other data that is normally given to f5 support for problem resolution.

     

     

    Both file types are compressed archives and if you are on windows then I recommend using 7zip to open them. Your f5 admin can get both from the gui for you, so that should help you out if they are pressed for time and do not like using the cli.

     

     

    Hope this helps,

     

     

    Carlb